[wp-trac] [WordPress Trac] #50195: Default esc_url scheme

WordPress Trac noreply at wordpress.org
Sun May 17 16:01:50 UTC 2020


#50195: Default esc_url scheme
-------------------------+-----------------------------
 Reporter:  Rahe         |      Owner:  (none)
     Type:  enhancement  |     Status:  new
 Priority:  normal       |  Milestone:  Awaiting Review
Component:  Security     |    Version:
 Severity:  normal       |   Keywords:
  Focuses:               |
-------------------------+-----------------------------
 Hello,

 By default esc_url will add http:// to the schemeless urls, in my opinion
 it's more secure to generate https links by default if scheme unknown, and
 let the users to deactive this if needed.

 Nicolas,

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/50195>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list